Documentation
¶
Overview ¶
Package sigstore implements the AnchorProvider interface using the Sigstore Rekor transparent log (https://rekor.sigstore.dev).
Rekor is a transparency log operated by the Linux Foundation / Sigstore project. Entries are append-only and immediately verifiable — once a log entry is created it is permanent, so Confirmation is returned as Finalized immediately after a successful Anchor call.
Implementation ¶
Each Anchor call generates an ephemeral ECDSA P-256 key pair, signs the Merkle root hash, and submits a hashedrekord v0.0.1 entry to Rekor via the github.com/sigstore/rekor Go client. The returned log entry UUID is stored as ExternalID and in ProofData for subsequent Verify calls.
For pilot / proof-of-concept use, the ephemeral signing key is not persisted. In production, a stable identity key should be used so that the signing identity is independently verifiable.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Config ¶
type Config struct {
// RekorURL is the base URL of the Rekor instance.
// Defaults to "https://rekor.sigstore.dev" when empty.
RekorURL string `json:"rekor_url,omitempty"`
}
Config holds configuration for the Sigstore Rekor anchor provider.
type Provider ¶
type Provider struct {
// contains filtered or unexported fields
}
Provider implements providers.AnchorProvider using Rekor.
func NewProvider ¶
NewProvider creates a new Sigstore Rekor anchor provider. Uses https://rekor.sigstore.dev by default.
func (*Provider) Anchor ¶
Anchor submits the Merkle root to the Rekor transparency log as a hashedrekord v0.0.1 entry. An ephemeral ECDSA P-256 key is generated per anchor to satisfy Rekor's signature requirement.
Returns Confirmation: Finalized immediately — Rekor entries are permanent once accepted into the append-only log.
func (*Provider) Verify ¶
func (p *Provider) Verify(ctx context.Context, anchor providers.Anchor) (providers.Verification, error)
Verify checks that the Rekor log entry still exists (expected always true for a properly operating transparency log). Implements swallow-transient-errors contract (§ 3.5c):
- Network errors and 5xx responses → Swallowed=true, confirmation preserved.
- 404 (entry missing from transparency log) → hard error (unexpected: log is append-only).
- Malformed ProofData → hard error.